Menu
Browse

Cyber Threat Actor: Pink

Updated 2026-08-21 17:17
Actor Type Location Known Incidents
 Icon
Criminal
1 incident
Characteristics
Threat actor characteristics available to members
Profile

Pink is an alias used by a threat actor group that has been observed in a series of intrusions against financial and private equity firms. The group’s activity became publicly known after a breach disclosed by Apollo on July 1 2026, in which attackers accessed the firm’s cloud environment. According to Apollo’s filing with the California attorney general, the intrusion began when employees were tricked into revealing credentials through spoofed helpdesk calls. The stolen data included names, birth dates, addresses and Social Security numbers of employees and possibly individuals linked to portfolio companies. The Apollo incident is described as part of a broader campaign in which actors using the aliases Falcon, Helix, Pink and Redact target similar organizations. The campaign’s stated objective appears to be the acquisition of personal data that can be leveraged for extortion, with ransom demands reported as high as seven hundred fifty thousand dollars. No public source indicates whether any ransom was paid in the Apollo case or in other intrusions attributed to the group. The targeting is limited to the financial and private equity sectors, with no explicit geographic focus mentioned in the available reporting. The strategic goal, as inferred from the disclosed ransom demands, is financial gain rather than espionage or disruption. No evidence links Pink to a state sponsor or to a known criminal consortium in the sources provided. The group’s activity is therefore characterized as financially motivated cybercrime focused on data theft for extortion. No additional details about the size, structure or revenue of the operation are publicly available.

The only technique explicitly referenced for Pink’s operations is social engineering via spoofed helpdesk calls to obtain employee credentials. This initial access vector allowed the attackers to move into Apollo’s cloud systems and exfiltrate the personal data sets described in the breach notice. No malware families, custom tools or specific command‑and‑control infrastructure are mentioned in the reporting, so the group’s tooling style remains unspecified. The exfiltration activity consisted of copying databases containing names, dates of birth, addresses and Social Security numbers, which were then used as leverage for ransom demands. The ransom aspect of the campaign is noted in the broader context, with some demands reaching up to seven hundred fifty thousand dollars, although the Apollo letter does not confirm a payment. Attribution to any particular nation‑state or organized crime group is absent from the public sources, leaving Pink’s affiliations undetermined. Consequently, the only confirmed campaign associated with the alias Pink is the Apollo breach, which serves as a representative example of the group’s method and intent. No further operations or dates are listed in the available material, so the profile is limited to the facts presented above.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources